Files
bsky-social-app/bskyweb
vineyardbovines f1d012000e fix(bskyweb): validate avatar URL scheme and bound fetch timeout
- Add SSRF defense: reject avatar URLs not starting with https://
- Add per-fetch timeout (5s) instead of relying on http.DefaultClient
- Document WebInviteWalletHero handler as unauthenticated by design
2026-06-25 16:38:57 -04:00
..
2024-04-13 12:20:06 -07:00
2024-04-13 12:20:06 -07:00
2024-04-13 12:20:06 -07:00
2024-04-13 12:20:06 -07:00
2026-05-18 09:51:04 -07:00
2024-04-13 12:20:06 -07:00
2024-04-13 12:20:06 -07:00

Build / Develop

SPA Bundle (monolithic static javascript file)

To build the SPA bundle (bundle.web.js), first get a JavaScript development environment set up. Either follow the top-level README, or something quick like:

# install nodejs
nvm install
nvm use
npm install --global pnpm

# setup tools and deps (in top level of this repo)
pnpm install --frozen-lockfile

# run pnpm web dev server, if you wanted
pnpm web

Then build and copy over the big 'ol bundle.web.js file:

# in the top level of this repo
pnpm build-web

Golang Daemon

Install golang. We generally develop against the current stable release of the language, as declared in go.mod.

In this directory (bskyweb/):

# re-build and run daemon
go run ./cmd/bskyweb serve

# build and output a binary
go build -o bskyweb ./cmd/bskyweb/

The easiest way to configure the daemon is to copy example.env to .env and fill in auth values there.